CVE-2026-12215 | xootix OTP Login & Register Woocommerce Plugin up to 2.7.2 on WordPress OTP Rate Limit login_user_with_otp ip_address excessive authentication

SecurityVulns

A vulnerability categorized as problematic has been discovered in xootix OTP Login & Register Woocommerce Plugin up to 2.7.2 on WordPress. Affected by this issue is the function login_user_with_otp of the component OTP Rate Limit. Such manipulation of the argument ip_address leads to improper restriction of excessive authentication attempts.

This vulnerability is documented as CVE-2026-12215. The attack can be executed remotely. There is not any exploit available.VulDB Recent EntriesRead More